Why digital ID needs more than technical compliance

Why digital ID needs more than technical compliance

Digital identity interoperability is moving into a new phase as conformance testing and self-certification for OpenID credential protocols become available, giving providers a way to test implementations against the standards themselves rather than relying solely on connections between individual systems.

For companies building infrastructure around European Digital Identity Wallets (EUDI Wallets), the shift could have significant implications for how digital identity systems are tested, deployed and scaled. Hopae’s analysis highlights the importance of the development for the wider ecosystem, particularly for providers building EUDI Wallet verification infrastructure across several EU Member States.

The standards at the centre of the testing framework are part of the OpenID4VC family, developed by the OpenID Foundation’s Digital Credentials Protocols Working Group. OpenID4VCI covers the issuance of digital credentials to wallets through an OAuth 2.0-based API, while OpenID4VP governs how wallets present those credentials to verifiers.

The High Assurance Interoperability Profile (HAIP) sits across both standards. Rather than creating another protocol, HAIP limits some of the implementation choices available within OpenID4VCI and OpenID4VP. It works alongside credential formats including IETF SD-JWT VC and ISO mdoc to create a more consistent technical baseline for high-assurance use cases.

OpenID4VP 1.0 reached Final status on 9 July 2025, followed by OpenID4VCI 1.0 on 16 September 2025 and HAIP 1.0 on 24 December 2025. Final status is significant because regulators generally require standards to reach this stage before they can be referenced directly in legislation.

The issue is that following the same specification does not necessarily mean two implementations will work together. OpenID4VCI and OpenID4VP allow developers to choose between different credential formats, signature algorithms, wallet invocation methods and client authentication approaches. While each option can comply with the underlying specification, different combinations can still prevent systems from interoperating.

HAIP addresses this by narrowing those choices for high-assurance implementations. Among other requirements, it supports SD-JWT VC or ISO mdoc credentials, ES256 signatures and SHA-256 digests. It also requires X.509 certificate-based issuer key resolution and excludes self-signed certificates.

For credential issuance, HAIP requires the Authorisation Code Flow, compliance with the FAPI 2.0 Security Profile, DPoP for sender-constrained tokens and wallet attestation. On the presentation side, it requires DCQL queries, response encryption using ephemeral keys and the x509_hash Client Identifier Prefix for signed requests.

The profile does not attempt to solve every aspect of digital identity interoperability. HAIP acknowledges that it does not cover all requirements for eIDAS Level of Assurance High, while trust management and some extension points remain the responsibility of individual ecosystems. Its role is therefore to provide a common technical baseline rather than a complete interoperability framework.

Until now, interoperability has often been assessed by connecting different implementations and checking whether they work together. That approach can identify compatibility issues, but it can also allow two systems to pass because they share the same interpretation of a specification. Pairwise testing also becomes increasingly difficult as the number of implementations grows.

The OpenID Foundation’s conformance suites take a different approach by testing implementations directly against the specification. They also include negative tests, which check whether systems correctly reject invalid requests. This is particularly important for verifiers, where accepting an incorrectly formed or invalid request could create security issues.

Hopae’s analysis of the interoperability process also highlights the shift from testing whether individual implementations work together to validating whether they correctly follow the underlying specifications. Hopae participated in an interoperability event in November 2025 focused on HAIP 1.0, ahead of the profile reaching Final status. Findings from the event were fed back into the Digital Credentials Protocols Working Group and used to inform the test suites.

OpenID4VP 1.0 with HAIP 1.0 subsequently achieved a 98% pass rate. The result points to a more structured approach to interoperability, allowing implementers to assess whether their systems meet the intended requirements before relying on integrations with individual counterparties.

Self-certification is now available for the relevant OpenID protocols. Under OpenID4VP, organisations can certify implementations as wallets or verifiers, while OpenID4VCI supports certification as issuers or wallet providers. Wallets can also certify against the W3C Browser API appendix of OpenID4VP, with the conformance tests available to run free of charge.

Read the Hopae analysis here

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.